Build Teleport Connect on darwin/amd64 (#12257)

This commit updates drone to build Teleport Connect by:

* cloning `gravitational/webapps` as a sibling directory to
  gravitational/teleport
* checkout out the right version of webapps by running a simple
  Go program (this step is only necessary until we move webapps
  into the teleport repo)
* Running the Teleport Connect build and copying artifacts

Code signing should run on tag builds automatically as part the
electron build, assuming the Apple Account credentials are
properly loaded into the keychain.

Notarization will also happen automatically if both 
`$APPLE_USERNAME` and `$APPLE_PASSWORD` are set.

In order to make the above happen, this patch also includes:

* Installing and removing a per-build Node instance in the 
  toolchain directory on Darwin
* Moving the toolchain temporary directory out of ~/ and into /tmp.

Drone usually sets `$HOME` to a temporary directory for each build,
but unfortunately we need it to point to the actual build user's 
home directory in order for the notarisation tooling to find the
right keychain. Having $HOME point to a long-lived directory risks
both pollution from build detritus and builds stomping on one another.

In an in an attempt to isolate the builds from each other and protect
`~build` as best we can, as much of the build state as possible 
(including ephemeral toolchains) has been moved under `/tmp`.

Co-authored-by: Trent Clarke <trent@goteleport.com>
This commit is contained in:
Zac Bergquist
2022-06-03 12:19:42 +10:00
committed by GitHub
co-authored by Trent Clarke
parent 4d76910b59
commit 86f3a3d618
9 changed files with 390 additions and 83 deletions
+134 -46
View File
@@ -446,7 +446,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/mac.go:32
# Generated at dronegen/mac.go:39
################################################
kind: pipeline
@@ -490,6 +490,11 @@ steps:
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .
- git checkout ${DRONE_TAG:-$DRONE_COMMIT}
- mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- git clone https://github.com/gravitational/webapps.git .
- git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa
&& chmod 600 $WORKSPACE_DIR/.ssh/id_rsa
- ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null
@@ -507,37 +512,64 @@ steps:
- name: Install Go Toolchain
commands:
- set -u
- mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz
- tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz
- tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz
- rm -rf $RUNTIME.darwin-amd64.tar.gz
environment:
RUNTIME: go1.18.3
- name: Install Rust Toolchain
commands:
- set -u
- export PATH=/Users/build/.cargo/bin:$PATH
- mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export PATH=/Users/$(whoami)/.cargo/bin:$PATH
- mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- rustup toolchain install $RUST_VERSION
environment:
WORKSPACE_DIR: /tmp/push-build-darwin-amd64
- name: Install Node Toolchain
commands:
- set -u
- export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-node-version)
- export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64
- mkdir -p $TOOLCHAIN_DIR
- curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz
- tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz
- rm -f node-v$NODE_VERSION-darwin-x64.tar.gz
- export PATH=$NODE_DIR/bin:$PATH
- corepack enable yarn
- echo Node reporting version $(node --version)
- echo Yarn reporting version $(yarn --version)
environment:
WORKSPACE_DIR: /tmp/push-build-darwin-amd64
- name: Build Mac artifacts
commands:
- set -u
- echo HOME=$${HOME}
- export HOME=/Users/$(whoami)
- export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-node-version)
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64
- export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- build.assets/build-fido2-macos.sh build
- export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)"
- rustup override set $RUST_VERSION
- make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- yarn install --frozen-lockfile && yarn build-term && yarn package-term
environment:
ARCH: amd64
GOCACHE: /tmp/push-build-darwin-amd64/go/cache
@@ -547,15 +579,16 @@ steps:
- name: Clean up toolchains (post)
commands:
- set -u
- export PATH=/Users/build/.cargo/bin:$PATH
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export PATH=/Users/$(whoami)/.cargo/bin:$PATH
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- rustup override unset
- rustup toolchain uninstall $RUST_VERSION
- rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED
environment:
WORKSPACE_DIR: /tmp/push-build-darwin-amd64
when:
@@ -1054,7 +1087,7 @@ steps:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -1211,7 +1244,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -1367,7 +1400,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -1521,7 +1554,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -1675,7 +1708,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -1856,7 +1889,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -2034,7 +2067,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -2201,7 +2234,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -2365,7 +2398,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -2519,7 +2552,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -2700,7 +2733,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -2867,7 +2900,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/mac.go:32
# Generated at dronegen/mac.go:39
################################################
kind: pipeline
@@ -2908,6 +2941,11 @@ steps:
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .
- git checkout ${DRONE_TAG:-$DRONE_COMMIT}
- mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- git clone https://github.com/gravitational/webapps.git .
- git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa
&& chmod 600 $WORKSPACE_DIR/.ssh/id_rsa
- ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null
@@ -2928,39 +2966,74 @@ steps:
- name: Install Go Toolchain
commands:
- set -u
- mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz
- tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz
- tar -C /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains -xzf $RUNTIME.darwin-amd64.tar.gz
- rm -rf $RUNTIME.darwin-amd64.tar.gz
environment:
RUNTIME: go1.18.3
- name: Install Rust Toolchain
commands:
- set -u
- export PATH=/Users/build/.cargo/bin:$PATH
- mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export PATH=/Users/$(whoami)/.cargo/bin:$PATH
- mkdir -p /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- rustup toolchain install $RUST_VERSION
environment:
WORKSPACE_DIR: /tmp/build-darwin-amd64
- name: Install Node Toolchain
commands:
- set -u
- export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-node-version)
- export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64
- mkdir -p $TOOLCHAIN_DIR
- curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz
- tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz
- rm -f node-v$NODE_VERSION-darwin-x64.tar.gz
- export PATH=$NODE_DIR/bin:$PATH
- corepack enable yarn
- echo Node reporting version $(node --version)
- echo Yarn reporting version $(yarn --version)
environment:
WORKSPACE_DIR: /tmp/build-darwin-amd64
- name: Build Mac release artifacts
commands:
- set -u
- echo HOME=$${HOME}
- export HOME=/Users/$(whoami)
- export TOOLCHAIN_DIR=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains
- export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-node-version)
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64
- export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- build.assets/build-fido2-macos.sh build
- export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)"
- rustup override set $RUST_VERSION
- security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain
- security find-identity -v
- make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- yarn install --frozen-lockfile && yarn build-term && yarn package-term
environment:
APPLE_PASSWORD:
from_secret: APPLE_PASSWORD
APPLE_USERNAME:
from_secret: APPLE_USERNAME
ARCH: amd64
BUILDBOX_PASSWORD:
from_secret: BUILDBOX_PASSWORD
GOCACHE: /tmp/build-darwin-amd64/go/cache
GOPATH: /tmp/build-darwin-amd64/go
OS: darwin
@@ -2971,8 +3044,12 @@ steps:
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts
- cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release
- cp *.dmg $WORKSPACE_DIR/go/artifacts
- cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256
$FILE > $FILE.sha256; done && ls -l
- cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE"
> "$FILE.sha256"; done && ls -l
environment:
WORKSPACE_DIR: /tmp/build-darwin-amd64
- name: Upload to S3
@@ -3036,15 +3113,16 @@ steps:
- name: Clean up toolchains (post)
commands:
- set -u
- export PATH=/Users/build/.cargo/bin:$PATH
- export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- export PATH=/Users/$(whoami)/.cargo/bin:$PATH
- export CARGO_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/cargo
- export RUST_HOME=$CARGO_HOME
- export RUSTUP_HOME=/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED/toolchains/rustup
- export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets
print-rust-version)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- rustup override unset
- rustup toolchain uninstall $RUST_VERSION
- rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains
- rm -rf /tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED
environment:
WORKSPACE_DIR: /tmp/build-darwin-amd64
when:
@@ -3063,7 +3141,7 @@ steps:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/mac.go:32
# Generated at dronegen/mac.go:39
################################################
kind: pipeline
@@ -3106,6 +3184,11 @@ steps:
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .
- git checkout ${DRONE_TAG:-$DRONE_COMMIT}
- mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- git clone https://github.com/gravitational/webapps.git .
- git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa
&& chmod 600 $WORKSPACE_DIR/.ssh/id_rsa
- ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null
@@ -3244,7 +3327,7 @@ steps:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/mac.go:32
# Generated at dronegen/mac.go:39
################################################
kind: pipeline
@@ -3287,6 +3370,11 @@ steps:
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .
- git checkout ${DRONE_TAG:-$DRONE_COMMIT}
- mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps
- git clone https://github.com/gravitational/webapps.git .
- git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)
- cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport
- mkdir -m 0700 $WORKSPACE_DIR/.ssh && echo "$GITHUB_PRIVATE_KEY" > $WORKSPACE_DIR/.ssh/id_rsa
&& chmod 600 $WORKSPACE_DIR/.ssh/id_rsa
- ssh-keyscan -H github.com > $WORKSPACE_DIR/.ssh/known_hosts 2>/dev/null
@@ -3425,7 +3513,7 @@ steps:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -3579,7 +3667,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -3733,7 +3821,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -3900,7 +3988,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -4067,7 +4155,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -4248,7 +4336,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:451
# Generated at dronegen/tag.go:461
################################################
kind: pipeline
@@ -4429,7 +4517,7 @@ volumes:
################################################
# Generated using dronegen, do not edit by hand!
# Use 'make dronegen' to update.
# Generated at dronegen/tag.go:240
# Generated at dronegen/tag.go:250
################################################
kind: pipeline
@@ -4589,7 +4677,7 @@ name: build-docker-images
environment:
BUILDBOX_VERSION: "teleport10"
RUNTIME: go1.18.2
RUNTIME: go1.17.9
trigger:
event:
@@ -5192,7 +5280,7 @@ steps:
- if [ "${DRONE_REPO}" != "gravitational/teleport" ]; then echo "---> Not publishing ${DRONE_REPO} packages to RPM and DEB repos" && exit 78; fi
- name: Check if tag is prerelease
image: golang:1.18-alpine
image: golang:1.17-alpine
commands:
- cd /go/src/github.com/gravitational/teleport/build.assets/tooling
- go run ./cmd/check -tag ${DRONE_TAG} -check prerelease || (echo '---> Not publishing ${DRONE_TAG} packages to RPM and DEB repos' && exit 78)
@@ -5273,7 +5361,7 @@ steps:
# that would cause apt users to downgrade. For more info see:
# https://github.com/gravitational/teleport/issues/8166
- name: Check if tag is latest
image: golang:1.18-alpine
image: golang:1.17-alpine
commands:
- cd /go/src/github.com/gravitational/teleport/build.assets/tooling
- go run ./cmd/check -tag ${DRONE_TAG} -check latest || (echo '---> Not publishing ${DRONE_REPO} packages to DEB repo' && exit 78)
@@ -5392,6 +5480,6 @@ volumes:
name: drone-s3-debrepo-pvc
---
kind: signature
hmac: b76936baf6cfee569080bcdf91de2167bdbfe0603d1b607026b666e820302ff8
hmac: e83f39ac80fa38122a8cf34a6202f36a6d08163e8a31c30ce2e7599222f8b103
...
+1 -1
View File
@@ -15,7 +15,7 @@ RUN BIN="/usr/local/bin" && \
chmod +x "${BIN}/${BINARY_NAME}"
# Install node
ARG NODE_VERSION=v15.14.0
ARG NODE_VERSION
ENV NODE_URL="https://nodejs.org/dist/${NODE_VERSION}/node-${NODE_VERSION}-linux-${BUILDARCH}.tar.xz"
ENV NODE_PATH="/usr/local/lib/node-${NODE_VERSION}-linux-${BUILDARCH}"
ENV PATH="$PATH:${NODE_PATH}/bin"
+9
View File
@@ -19,6 +19,7 @@ ARCH ?= amd64
BUILDBOX_VERSION ?= teleport10
GOLANG_VERSION ?= go1.18.3
RUST_VERSION ?= 1.61.0
NODE_VERSION ?= 16.13.2
BORINGCRYPTO_RUNTIME=$(GOLANG_VERSION)b7
LIBBPF_VERSION ?= 0.3.1
@@ -213,6 +214,7 @@ buildbox-teleterm: buildbox
@if [[ $${DRONE} == "true" ]] && ! docker inspect --type=image $(BUILDBOX_TELETERM) 2>&1 >/dev/null; then docker pull $(BUILDBOX_TELETERM) || true; fi;
docker build \
--build-arg BUILDBOX_VERSION=$(BUILDBOX_VERSION) \
--build-arg NODE_VERSION=$(NODE_VERSION) \
--build-arg BUILDARCH=$(RUNTIME_ARCH) \
--build-arg GRPC_NODE_PLUGIN_BINARY_TYPE=$(GRPC_NODE_PLUGIN_BINARY_TYPE) \
--cache-from $(BUILDBOX) \
@@ -444,6 +446,13 @@ print-go-version:
print-rust-version:
@echo $(RUST_VERSION)
#
# Print the Node version used to build Teleport Connect.
#
.PHONY:print-node-version
print-node-version:
@echo $(NODE_VERSION)
#
# Print the buildbox version used to build Teleport.
#
@@ -0,0 +1,48 @@
// Copyright 2022 Gravitational, Inc
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
// Command get-webapps-version determines the appropriate version
// of webapps to check out for a given version of teleport.
package main
import (
"fmt"
"os"
"strings"
)
func main() {
fmt.Println(webappsVersion(
os.Getenv("DRONE_TAG"),
os.Getenv("DRONE_TARGET_BRANCH"),
))
}
func webappsVersion(tag, targetBranch string) string {
// if this build was triggered from a tag on the
// gravitational/teleport repo, assume that same
// tag exists on gravitational/webapps
if tag != "" {
return tag
}
// if this build is on one of the teleport release branches,
// map to the equivalent release branch in webapps
if strings.HasPrefix(targetBranch, "branch/") {
return "teleport-" + strings.TrimPrefix(targetBranch, "branch/")
}
// otherwise, this is a build on master, so just use master on webapps
return "master"
}
@@ -0,0 +1,39 @@
// Copyright 2022 Gravitational, Inc
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package main
import (
"testing"
"github.com/stretchr/testify/require"
)
func TestWebappsVersion(t *testing.T) {
for _, test := range []struct {
desc string
droneTag string
targetBranch string
want string
}{
{desc: "prefer tag", droneTag: "v9.2.0", want: "v9.2.0"},
{desc: "maps branches", targetBranch: "branch/v9", want: "teleport-v9"},
{desc: "fallback master", targetBranch: "foobar", want: "master"},
} {
t.Run(test.desc, func(t *testing.T) {
require.Equal(t, test.want,
webappsVersion(test.droneTag, test.targetBranch))
})
}
}
+4
View File
@@ -162,6 +162,10 @@ func (b *buildType) Description(packageType string, extraQualifications ...strin
return result
}
func (b *buildType) hasTeleportConnect() bool {
return b.os == "darwin" && b.arch == "amd64"
}
// dockerService generates a docker:dind service
// It includes the Docker socket volume by default, plus any extra volumes passed in
func dockerService(v ...volumeRef) service {
+144 -35
View File
@@ -19,6 +19,13 @@ import (
"path"
)
const (
perBuildDir = "/tmp/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED"
perBuildToolchainsDir = perBuildDir + "/toolchains"
perBuildCargoDir = perBuildToolchainsDir + "/cargo"
perBuildRustupDir = perBuildToolchainsDir + "/rustup"
)
// escapedPreformatted returns expr wrapped in escaped backticks,
// resulting in Slack "preformatted" string, but safe to use in bash
// without triggering the command expansion.
@@ -37,8 +44,13 @@ func newDarwinPipeline(name string) pipeline {
}
func darwinPushPipeline() pipeline {
b := buildType{os: "darwin", arch: "amd64"}
p := newDarwinPipeline("push-build-darwin-amd64")
p.Trigger = triggerPush
p.Trigger = trigger{
Event: triggerRef{Include: []string{"push"}, Exclude: []string{"pull_request"}},
Branch: triggerRef{Include: []string{"master", "branch/*"}},
Repo: triggerRef{Include: []string{"gravitational/*"}},
}
p.Steps = []step{
setUpExecStorageStep(p.Workspace.Path),
{
@@ -47,10 +59,11 @@ func darwinPushPipeline() pipeline {
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"},
},
Commands: pushCheckoutCommandsDarwin(),
Commands: pushCheckoutCommandsDarwin(b),
},
installGoToolchainStep(),
installRustToolchainStep(p.Workspace.Path),
installNodeToolchainStep(p.Workspace.Path),
{
Name: "Build Mac artifacts",
Environment: map[string]value{
@@ -60,7 +73,7 @@ func darwinPushPipeline() pipeline {
"ARCH": {raw: "amd64"},
"WORKSPACE_DIR": {raw: p.Workspace.Path},
},
Commands: darwinTagBuildCommands(),
Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: false}),
},
cleanUpToolchainsStep(p.Workspace.Path),
cleanUpExecStorageStep(p.Workspace.Path),
@@ -101,27 +114,36 @@ func darwinTagPipeline() pipeline {
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"},
},
Commands: darwinTagCheckoutCommands(),
Commands: darwinTagCheckoutCommands(b),
},
installGoToolchainStep(),
installRustToolchainStep(p.Workspace.Path),
installNodeToolchainStep(p.Workspace.Path),
{
Name: "Build Mac release artifacts",
Environment: map[string]value{
"GOPATH": {raw: path.Join(p.Workspace.Path, "/go")},
"GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")},
"OS": {raw: b.os},
"ARCH": {raw: b.arch},
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"GOPATH": {raw: path.Join(p.Workspace.Path, "/go")},
"GOCACHE": {raw: path.Join(p.Workspace.Path, "/go/cache")},
"OS": {raw: b.os},
"ARCH": {raw: b.arch},
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"BUILDBOX_PASSWORD": {fromSecret: "BUILDBOX_PASSWORD"},
// These credentials are necessary for the signing and notarization of
// Teleport Connect, which is built in to the Electron tooling.
// The rest of the mac artifacts are signed and notarized with gon
// in the darwin pkg pipeline.
"APPLE_USERNAME": {fromSecret: "APPLE_USERNAME"},
"APPLE_PASSWORD": {fromSecret: "APPLE_PASSWORD"},
},
Commands: darwinTagBuildCommands(),
Commands: darwinTagBuildCommands(b, darwinBuildOptions{unlockKeychain: true}),
},
{
Name: "Copy Mac artifacts",
Environment: map[string]value{
"WORKSPACE_DIR": {raw: p.Workspace.Path},
},
Commands: darwinTagCopyPackageArtifactCommands(),
Commands: darwinTagCopyPackageArtifactCommands(b),
},
{
Name: "Upload to S3",
@@ -140,8 +162,8 @@ func darwinTagPipeline() pipeline {
Failure: "ignore",
Environment: map[string]value{
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"RELEASES_CERT": value{fromSecret: "RELEASES_CERT_STAGING"},
"RELEASES_KEY": value{fromSecret: "RELEASES_KEY_STAGING"},
"RELEASES_CERT": {fromSecret: "RELEASES_CERT_STAGING"},
"RELEASES_KEY": {fromSecret: "RELEASES_KEY_STAGING"},
},
},
cleanUpToolchainsStep(p.Workspace.Path),
@@ -150,13 +172,27 @@ func darwinTagPipeline() pipeline {
return p
}
func pushCheckoutCommandsDarwin() []string {
return []string{
func pushCheckoutCommandsDarwin(b buildType) []string {
commands := []string{
`set -u`,
`mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
`git clone https://github.com/gravitational/${DRONE_REPO_NAME}.git .`,
`git checkout ${DRONE_TAG:-$DRONE_COMMIT}`,
}
// clone github.com/gravitational/webapps for the Teleport Connect source code
if b.hasTeleportConnect() {
commands = append(commands,
`mkdir -p $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`,
`git clone https://github.com/gravitational/webapps.git .`,
`git checkout $(go run $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets/tooling/cmd/get-webapps-version/main.go)`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
)
}
commands = append(commands,
// fetch enterprise submodules
// suppressing the newline on the end of the private key makes git operations fail on MacOS
// with an error like 'Load key "/path/.ssh/id_rsa": invalid format'
@@ -168,7 +204,9 @@ func pushCheckoutCommandsDarwin() []string {
`GIT_SSH_COMMAND='ssh -i $WORKSPACE_DIR/.ssh/id_rsa -o UserKnownHostsFile=$WORKSPACE_DIR/.ssh/known_hosts -F /dev/null' git submodule update --init --recursive webassets || true`,
`rm -rf $WORKSPACE_DIR/.ssh`,
`mkdir -p $WORKSPACE_DIR/go/cache`,
}
)
return commands
}
func setUpExecStorageStep(path string) step {
@@ -192,9 +230,9 @@ func installGoToolchainStep() step {
},
Commands: []string{
`set -u`,
`mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`mkdir -p ` + perBuildToolchainsDir,
`curl --silent -O https://dl.google.com/go/$RUNTIME.darwin-amd64.tar.gz`,
`tar -C ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains -xzf $RUNTIME.darwin-amd64.tar.gz`,
`tar -C ` + perBuildToolchainsDir + ` -xzf $RUNTIME.darwin-amd64.tar.gz`,
`rm -rf $RUNTIME.darwin-amd64.tar.gz`,
},
}
@@ -206,16 +244,38 @@ func installRustToolchainStep(path string) step {
Environment: map[string]value{"WORKSPACE_DIR": {raw: path}},
Commands: []string{
`set -u`,
`export PATH=/Users/build/.cargo/bin:$PATH`,
`mkdir -p ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`export PATH=/Users/$(whoami)/.cargo/bin:$PATH`, // use the system-installed rustup to install our custom Rust version
`mkdir -p ` + perBuildToolchainsDir,
`export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`,
`export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`export CARGO_HOME=` + perBuildCargoDir,
`export RUST_HOME=$CARGO_HOME`,
`export RUSTUP_HOME=` + perBuildRustupDir,
`rustup toolchain install $RUST_VERSION`,
},
}
}
func installNodeToolchainStep(workspacePath string) step {
return step{
Name: "Install Node Toolchain",
Environment: map[string]value{"WORKSPACE_DIR": {raw: workspacePath}},
Commands: []string{
`set -u`,
`export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`,
`export TOOLCHAIN_DIR=` + perBuildToolchainsDir,
`export NODE_DIR=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`,
`mkdir -p $TOOLCHAIN_DIR`,
`curl --silent -O https://nodejs.org/dist/v$NODE_VERSION/node-v$NODE_VERSION-darwin-x64.tar.gz`,
`tar -C $TOOLCHAIN_DIR -xzf node-v$NODE_VERSION-darwin-x64.tar.gz`,
`rm -f node-v$NODE_VERSION-darwin-x64.tar.gz`,
`export PATH=$NODE_DIR/bin:$PATH`,
`corepack enable yarn`,
`echo Node reporting version $(node --version)`,
`echo Yarn reporting version $(yarn --version)`,
},
}
}
func cleanUpToolchainsStep(path string) step {
return step{
Name: "Clean up toolchains (post)",
@@ -225,16 +285,17 @@ func cleanUpToolchainsStep(path string) step {
},
Commands: []string{
`set -u`,
`export PATH=/Users/build/.cargo/bin:$PATH`,
`export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`export PATH=/Users/$(whoami)/.cargo/bin:$PATH`,
`export CARGO_HOME=` + perBuildCargoDir,
`export RUST_HOME=$CARGO_HOME`,
`export RUSTUP_HOME=` + perBuildRustupDir,
`export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
// clean up the rust toolchain even though we're about to delete the directory
// this ensures we don't leave behind a broken link
`rustup override unset`,
`rustup toolchain uninstall $RUST_VERSION`,
`rm -rf ~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`rm -rf ` + perBuildDir,
},
}
}
@@ -251,39 +312,87 @@ func cleanUpExecStorageStep(path string) step {
}
}
func darwinTagCheckoutCommands() []string {
return append(pushCheckoutCommandsDarwin(),
func darwinTagCheckoutCommands(b buildType) []string {
return append(
pushCheckoutCommandsDarwin(b),
`mkdir -p $WORKSPACE_DIR/go/artifacts`,
`echo "${DRONE_TAG##v}" > $WORKSPACE_DIR/go/.version.txt`,
`cat $WORKSPACE_DIR/go/.version.txt`,
)
}
func darwinTagBuildCommands() []string {
return []string{
type darwinBuildOptions struct {
unlockKeychain bool
}
func darwinTagBuildCommands(b buildType, opts darwinBuildOptions) []string {
commands := []string{
`set -u`,
`echo HOME=$${HOME}`,
`export HOME=/Users/$(whoami)`,
`export TOOLCHAIN_DIR=` + perBuildToolchainsDir,
`export NODE_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-node-version)`,
`export RUST_VERSION=$(make -C $WORKSPACE_DIR/go/src/github.com/gravitational/teleport/build.assets print-rust-version)`,
`export CARGO_HOME=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains`,
`export CARGO_HOME=` + perBuildCargoDir,
`export RUST_HOME=$CARGO_HOME`,
`export PATH=~/build-$DRONE_BUILD_NUMBER-$DRONE_BUILD_CREATED-toolchains/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$PATH`,
`export RUSTUP_HOME=` + perBuildRustupDir,
`export NODE_HOME=$TOOLCHAIN_DIR/node-v$NODE_VERSION-darwin-x64`,
`export PATH=$TOOLCHAIN_DIR/go/bin:$CARGO_HOME/bin:/Users/build/.cargo/bin:$NODE_HOME/bin:$PATH`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
`build.assets/build-fido2-macos.sh build`,
`export PKG_CONFIG_PATH="$(build.assets/build-fido2-macos.sh pkg_config_path)"`,
`rustup override set $RUST_VERSION`,
`make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`,
}
if opts.unlockKeychain {
commands = append(commands,
`security unlock-keychain -p $${BUILDBOX_PASSWORD} login.keychain`,
`security find-identity -v`,
)
}
commands = append(commands,
`make clean release OS=$OS ARCH=$ARCH FIDO2=yes TOUCHID=yes`,
)
if b.hasTeleportConnect() {
commands = append(commands,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps`,
`yarn install --frozen-lockfile && yarn build-term && yarn package-term`,
)
}
return commands
}
func darwinTagCopyPackageArtifactCommands() []string {
return []string{
func darwinTagCopyPackageArtifactCommands(b buildType) []string {
commands := []string{
`set -u`,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/teleport`,
// copy release archives to artifact directory
`cp teleport*.tar.gz $WORKSPACE_DIR/go/artifacts`,
`cp e/teleport-ent*.tar.gz $WORKSPACE_DIR/go/artifacts`,
// generate checksums (for mac)
`cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`,
}
// copy Teleport Connect artifacts
if b.hasTeleportConnect() {
commands = append(commands,
`cd $WORKSPACE_DIR/go/src/github.com/gravitational/webapps/packages/teleterm/build/release`,
`cp *.dmg $WORKSPACE_DIR/go/artifacts`,
)
}
// generate checksums
commands = append(commands,
`cd $WORKSPACE_DIR/go/artifacts && for FILE in teleport*.tar.gz; do shasum -a 256 $FILE > $FILE.sha256; done && ls -l`,
)
if b.hasTeleportConnect() {
commands = append(commands,
`cd $WORKSPACE_DIR/go/artifacts && for FILE in *.dmg; do shasum -a 256 "$FILE" > "$FILE.sha256"; done && ls -l`,
)
}
return commands
}
func darwinUploadToS3Commands() []string {
+1 -1
View File
@@ -36,7 +36,7 @@ func darwinPkgPipeline(name, makeTarget string, pkgGlobs []string, extraQualific
"WORKSPACE_DIR": {raw: p.Workspace.Path},
"GITHUB_PRIVATE_KEY": {fromSecret: "GITHUB_PRIVATE_KEY"},
},
Commands: darwinTagCheckoutCommands(),
Commands: darwinTagCheckoutCommands(b),
},
{
Name: "Download built tarball artifacts from S3",
+10
View File
@@ -82,6 +82,16 @@ func tagBuildCommands(b buildType) []string {
),
)
// Build Teleport Connect on suported OS/arch
if b.hasTeleportConnect() {
commands = append(commands,
`cd /go/src/github.com/gravitational/webapps`,
`yarn install --frozen-lockfile && yarn build-term && yarn package-term`,
`cd -`,
)
}
if b.os == "windows" {
commands = append(commands,
`rm -f windows-signing-cert.pfx`,